Impact
Protocol::HTTP2 versions before 1.14 for Perl have a flaw where closed streams are retained in the connection stream table, causing a memory leak. When an HTTP/2 stream ends, the module clears most of the stream’s data but does not remove the entry, so each subsequent closed stream keeps a small residual allocation. An attacker can repeatedly open and close streams over a long‑lived connection, causing the server’s memory usage to grow linearly and potentially exhaust available memory, leading to denial of service.
Affected Systems
Any deployment of the Perl module Protocol::HTTP2 that processes HTTP/2 connections and uses a version earlier than 1.14 is affected. The issue is present in releases such as 1.13 and earlier.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for a remote memory‑exhaustion vulnerability. The EPSS score of < 1 % suggests that exploitation is currently unlikely, and the CVE is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker establishing a long‑lived HTTP/2 connection to the vulnerable server and repeatedly creating and closing streams; each cycle leaves a residual table entry that increases the server’s resident memory. Successful exploitation would require sustained traffic, but if achieved it could push the server to run out of memory or force a restart, thereby denying service to legitimate users.
OpenCVE Enrichment